A personal Security Operations Center (SOC) lab environment built for hands-on blue team training, threat detection, and DFIR practice. This project documents my journey in building a segmented network with enterprise-grade security monitoring capabilities on a home lab budget.
- Overview
- Architecture
- Hardware Specifications
- Network Design
- Security Stack
- Use Cases & Projects
- Challenges & Solutions
- Future Improvements
This home lab simulates a small enterprise network with proper segmentation, traffic monitoring, and log analysis capabilities. The primary goal is to develop practical SOC analyst skills through:
- Real-time network traffic analysis
- Log aggregation and SIEM operations
- Intrusion detection and alerting
- Digital forensics and incident response (DFIR) practice
The environment follows a defense-in-depth approach with network segmentation enforced at the firewall level.
ISP Router
β
βΌ (WAN)
βββββββββββββββββββββββββββββββββββ
β pfSense Firewall β
β Zeek + Suricata (IDS/NSM) β
βββββββββββββββββββββββββββββββββββ
β (LAN - Trunk)
βΌ
βββββββββββββββββββββββββββββββββββ
β TP-Link TL-SG105E β
β (Managed Switch) β
ββββββββββββββββββ¬βββββββββββββββββ€
β VLAN 10 β VLAN 20 β
β Users Network β Servers Networkβ
β 10.10.10.0/24 β192.168.10.0/24 β
ββββββββββββββββββ΄βββββββββββββββββ
β
βΌ
βββββββββββββββββββ
β Proxmox Server β
β192.168.10.x β
βββββββββββββββββββ€
β VMs: β
β β’ Arch Server β
β β’ Security Onionβ
β β’ Splunk β
β β’ Kali Linux β
β β’ Arch HTB β
β β’ Win11 β
βββββββββββββββββββ
| Component | Specification |
|---|---|
| CPU | Intel Core i5-12500 (12 cores) |
| RAM | 32 GB DDR4 |
| Storage | 1 TB NVMe SSD + 1 TB HDD |
| GPU | Integrated (APU) |
| Device | Model | Role |
|---|---|---|
| Firewall | Repurposed Laptop | pfSense + Zeek + Suricata |
| Switch | TP-Link TL-SG105E | VLAN Management (5 ports) |
| VLAN ID | Name | Subnet | Purpose | Switch Ports |
|---|---|---|---|---|
| 10 | Users | 10.10.10.0/24 | Personal devices, isolated from servers | 2 |
| 20 | Servers | 192.168.10.0/24 | Lab VMs, security tools, Proxmox | 2 |
- Users VLAN β Servers VLAN: Blocked by default
- Servers VLAN β Users VLAN: Blocked by default
- Inter-VLAN routing: Denied unless explicitly required
- Outbound: Allowed with logging for analysis
This segmentation ensures that even if a device on the Users network is compromised, lateral movement to the lab environment is prevented.
| VM | OS | Purpose | Status |
|---|---|---|---|
| Arch Server | Arch Linux + Docker | CyberChef, n8n, core services | Always On |
| Security Onion | Security Onion | Network security monitoring (Standalone) | On-demand |
| Splunk | Debian | SIEM, log aggregation, alerting | On-demand |
| HTB-Arch | Arch Linux (Custom) | HackTheBox Sherlock challenges, DFIR | On-demand |
| Kali Linux | Kali | Penetration testing, red team simulations | On-demand |
| Win11-Lab | Windows 11 | Malware analysis, Windows forensics | On-demand |
| Container | Purpose |
|---|---|
| CyberChef | Data encoding/decoding, analysis |
| n8n | Workflow automation, future LLM integration |
Network Traffic
β
βΌ
βββββββββββββββββββββββββββββββββββββββ
β pfSense Firewall β
β βββββββββββββββ ββββββββββββββββ β
β β Zeek β β Suricata β β
β β (Metadata) β β (IDS/IPS) β β
β ββββββββ¬βββββββ ββββββββ¬ββββββββ β
βββββββββββΌβββββββββββββββββΌβββββββββββ
β β
βββββββββ¬βββββββββ
βΌ
ββββββββββββββ
β Splunk β
β (SIEM) β
βββββββ¬βββββββ
β (Planned)
βΌ
ββββββββββββββ
β n8n β
β + LLM API β
β(Automation)β
ββββββββββββββ
Log Sources:
- Zeek connection logs, DNS, HTTP, SSL metadata
- Suricata alerts (ET Open ruleset)
- pfSense firewall logs
Completed DFIR challenges using this lab environment:
| Challenge | Category | Skills Practiced |
|---|---|---|
| Brutus | Auth Log Analysis | Linux authentication forensics |
| Meerkat | Network Analysis | PCAP analysis, C2 detection |
| Unit42 | Malware Analysis | Static/dynamic analysis |
| PhishNet | Email Forensics | Phishing email analysis, IOC extraction |
| Campfire-1 | Windows Forensics | Event log analysis |
π Writeups available in my DFIR-Writeups repository
- Verified Security Onion detection capabilities using Nmap scans from Users VLAN
- Tested alert generation for reconnaissance activities
Problem: The laptop repurposed as a pfSense firewall lacks USB 3.0 ports. The external USB Ethernet adapter (required for WAN connection) operates on USB 2.0, causing intermittent connectivity issues and latency spikes.
Impact:
- Occasional packet loss during high-throughput scenarios
- Zeek/Suricata may miss packets during traffic bursts
Current Workaround:
- Monitoring for connection drops
- Considering dedicated low-power hardware (e.g., Protectli Vault, used Dell OptiPlex) for future upgrade
Lessons Learned:
- Hardware limitations matter in network security
- USB Ethernet adapters are not ideal for firewall deployments
- Plan hardware requirements before building the lab
- Replace pfSense laptop with dedicated mini PC
- Add dedicated SPAN port for Security Onion
- Implement Wazuh for endpoint detection (EDR)
- LLM-powered log analysis β Integrate local LLM with n8n for automated log summarization, anomaly detection, and server health monitoring
- Create attack simulations with Atomic Red Team
- Add Velociraptor for endpoint forensics
- Document more HackTheBox Sherlock writeups
homelab-soc-environment/
βββ diagrams/
β βββ network-topology.png
βββ configurations/
βββ pfsense-firewall-rules.md
βββ vlan-setup.md
- Network segmentation and VLAN configuration
- Firewall rule design and implementation
- IDS/IPS deployment (Suricata)
- Network Security Monitoring (Zeek)
- SIEM administration (Splunk)
- Virtualization (Proxmox)
- Digital Forensics and Incident Response (DFIR)
- GitHub: github.com/f23783
- LinkedIn: https://www.linkedin.com/in/arda-fidanc%C4%B1-50a0a9305/
This project is part of my journey to becoming a SOC Analyst. Feedback and suggestions are welcome!
